Family Computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by spamdragon, Jan 27, 2015.

  1. spamdragon

    spamdragon Private E-2

    Thank you in advance.

    This is a family computer shared by my wife and children. They often play simple flash-based games, and I'm worried they may have introduced some bad things here.

    Programs were run from my admin (bc) account, however I tend to notice the issues more on my wife's user (lynn) account. I constantly see blocked web attempt warnings from eset, even when a browser is not open.

    CCleaner had a hard time deleting the appdata/local/temp logs from my wife's account. The files were very slow to delete, and it seemed to be filling up with new ones constantly. I eventually unplugged the network cable and started killing any processes that I didn't recognize. It was a bit of whack-a-mole as new ones would pop up with weird names as soon as I killed one for a while, before it seemed to stop.

    Logs attached. Note mb was run twice, as I neglected to update definitions before running the first time around.

    Once again, thank you for your help.
     
  2. spamdragon

    spamdragon Private E-2

    logs
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    Re run Hitman and have it remove all that it finds.

    Now do this:

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Also once we are done with this account, I think we should focus on running all the tools on the Lynn account. :)
     
  4. spamdragon

    spamdragon Private E-2

    Done, logs attached.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look good, how are things running? We need to get to this Lynn account
     
  6. spamdragon

    spamdragon Private E-2

    I didn't see any problems with the first account.

    Unfortunately the second account seems to still be having quite a few problems. Randomly, I'm unable to disable the eset protection/firewall. Many applications will also not always start using "run as administrator" including Hitman for example (I ran it as another user to get it to run).

    eset does pop up fairly regular warnings about REG/Agent.AK trojan and JS/Exploid.Agent.NIX trojan, which it claims it deletes or quarantines, but I do see it pop up across reboots, even when the browser is not open. RK popped up a window about Poweliks removal, but I did not yet follow those instructions. MGlogs were dropped in a different directory because this user could not run it as admin, and I'm assuming then didn't have access to the C:\ root.

    I ran the programs where I could. As mentioned, Hitman was run as another user to get it to start in admin mode. tdsskiller had an issue starting the log and kept trying to load another driver & reboot but that wouldn't finish either.

    I'm also going to work to uninstall some programs that are no longer needed/wanted. This is a touchscreen that came loaded with a bunch of apps we never use and it might help to clear out some of the clutter.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I still need logs from Malware Bytes and RogueKiller please. Thanks.
     
  8. spamdragon

    spamdragon Private E-2

    They were zipped in the "hitman mb rk.zip" file due to the limit on # files that can be uploaded. Thanks!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This account has a poweliks infection...


    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  10. spamdragon

    spamdragon Private E-2

    done
     

    Attached Files:

  11. spamdragon

    spamdragon Private E-2

    "Run as admin" didn't seem to work again so I re-ran it using "run as different user" - the log looks more complete.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening.

    [​IMG] Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [Tr.Poweliks] (X64) HKEY_USERS\S-1-5-21-4121290062-3137879709-2513227565-1003\Software\classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LocalServer32 -> Found

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now re run RogueKiller and attach log.


    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     

    Attached Files:

  13. spamdragon

    spamdragon Private E-2

    Seems more responsive tonight.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I may have made a blooper in the way I had you run FRST. Could you run it again please just like in post # 9 and attach latest log.
     
  15. spamdragon

    spamdragon Private E-2

    here you go
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Roguekiller still finding that entry.....I need you to uninstall your anti virus please. (Is it ESET?) Once done, re run the RogueKiller instruction in post # 12.

    Once done... rescan with RogueKiller and attach log.
     
  17. spamdragon

    spamdragon Private E-2

    Nothing is showing up in RK. Attached the log to verify...?
    I did install eset... the license expired anyway and I'll probably go a different direction.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. :) How are things running? Ready for final steps?
     
  19. spamdragon

    spamdragon Private E-2

    Yep, looks pretty good at this point, thanks!
    Let's finish it up.

    Really appreciate your help.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds